PT-2017-16375 · Netiq · Netiq Access Manager

Published

2017-04-20

·

Updated

2017-07-11

·

CVE-2017-5190

CVSS v2.0

3.5

Low

VectorAV:N/AC:M/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions NetIQ Access Manager versions 4.2 before SP3 HF1 and 4.3 before SP1 HF1
Description The issue is related to a concurrency problem that causes information leakage when NetIQ Access Manager is configured as a SAML 2.0 Identity Server with Virtual Attributes. This is due to a stale profile.
Recommendations For versions 4.2 before SP3 HF1, update to SP3 HF1 or later to resolve the issue. For versions 4.3 before SP1 HF1, update to SP1 HF1 or later to resolve the issue.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-5190

Affected Products

Netiq Access Manager